Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Originally, the krb5login page would allow redirects to any URLs, e.g. to Google using http://$HOSTNAME/auth/krb5login/?next=//www.google.com. This commit implements similar sanitization of REDIRECT_FIELD_NAME like Django does in its LoginView. Related: https://github.com/django/django/blob/8fcb9f1f106cf60d953d88aeaa412cc625c60029/django/contrib/auth/views.py#L43C18-L43C18
- Loading branch information